Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-297x-j9pm-xjgg

Опубликовано: 23 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Drupal Core Remote Code Execution Vulnerability

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

Пакеты

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 7.0, < 7.59

7.59

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 8.0, < 8.4.8

8.4.8

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 8.5, < 8.5.3

8.5.3

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 7.0, < 7.59

7.59

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 8.0, < 8.4.8

8.4.8

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 8.5, < 8.5.3

8.5.3

EPSS

Процентиль: 100%
0.94316
Критический

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 7 лет назад

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

CVSS3: 9.8
nvd
почти 7 лет назад

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

CVSS3: 9.8
debian
почти 7 лет назад

A remote code execution vulnerability exists within multiple subsystem ...

EPSS

Процентиль: 100%
0.94316
Критический

9.8 Critical

CVSS3

Дефекты

CWE-94